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DIRECTOR OF CENTRAL INTELLIGENCE 
Security Committee SECOM-D-604 


9 AUG 1979 


MEMORANDUM FOR: SECOM Members 
Chairman, Compartmentation Subcommittee 


FROM: Robert W. Gambino 
Chairman 
SUBJECT: Revision of DCID 1/11 =] 25X1 


1. Members agreed at the March 1979 SECOM conference 
that a revision of DCID 1/11 should be prepared by the 
Committee staff for review and action by the Committee. A 
first draft was distributed to subcommittee chairmen, and 
their suggestions accommodated. That draft was not sub- 
mitted to the Compartmentation Subcommittee or SECOM members 
pending the then anticipated early resolution of proposals 
on the APEX system. The need to bring our charter up to 
date, particularly with regard to tasking to the DCI in 
Executive Orders 12036 and 12065, requires that we proceed 
with the effort now without waiting for final decision on 
APEX. 


2. <A draft revision of DCID 1/11 is attached. Some 
major changes are: 


a. An unauthorized disclosures investigations 
subcommittee is established with a charter. [| 25X11 


b. At the request of the Computer Security 
Subcommittee chairman, that group's responsibility 


is broadened to include intelligence information 
communicated by computers. [ ] 25X14 
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d. References to Executive Orders have been 
updated and new or changed tasking reflected in 
the draft. 


3. Addressees are requested to review the attachment 


and provide their concurrence or comments to the Executive 
Secretary not later than September 7, 1979. The staff point 


of contact for specific issues is 
25X1A 


ambino 


Attachment 
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DIRECTOR OF CENTRAL INTELLIGENCE DIRECTIVE NO. ry pl 


SECURITY COMMITTEE 


Pursuant to Section 102 of the National Security Act 
of 1947, Executive Orders 12036 and 12065, and National Security 
Council directives, a Security Committee is hereby established 
as a standing Director of Central Intelligence Committee with 
the following mission and functions. 
1. Mission 
The mission of the committee is to advise and assist 
the Director of Central Intelligence in meeting his security 
responsibilities by: 
a. Ensuring establishment of uniform 
security policies and procedures including 
recommendations for legislation for the protection 
of intelligence information i from unauthorized 


disclosure. 


this directive supersedes DCID No. 1/11 effective 18 May 1976. 
eer purposes of this directive the term "intelligence infor- 
mation means: 


(a) "Foreign intelligence’ and "counterintelligence’ as 
al ee lr der 
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b. Reviewing and formulating personnel, physical 
and information security policies, standards, 
practices and dissemination procedures applicable to 
all organizations of the Executive Branch as such 
policies, standards, practices and procedures relate 
to the protection of intelligence information in con- 
sideration of the effectiveness, risks and cost factors 
involved. 

c. Reviewing and formulating security policies 
and procedures bearing on the release of intelligence 
information to foreign governments and international 
organizations and on the review of classified intelligence 
information proposed for release to the public through 
declassification or other action. With respect to foreign 


release, ensuring that the information involved will be 


those terms are defined in Executive Order 12036; and 

(b) Information describing US foreign intelligence 
and counterintelligence sources and methods, activities, 
equipment and techniques used for the acquisition or 
exploitation of foreign intelligence and counterintelligence, 
foreign material obtained for intelligence exploitation, and 
imagery or data recordings resulting from US intelligence 


collection efforts. 
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accorded a degree of protection equal to that afforded 


by the United States. With respect to public release, 


ensuring that actions are taken pursuant to proper 


authority and that they are accomplished so as to 
minimize the risk to other intelligence information. 

d. Reviewing and formulating procedures to aid 
in maintaining the security of national foreign intel- 
ligence products provided the Congress. 

e. Ensuring the development, review and use of 
effective means to defend sensitive US installations 
Or activities against technical surveillance. 

f. Reviewing special access programs governed by 
section 4-2 of Executive Order 12065 and compartmentation 
procedures and recommending changes as necessary to 
achieve optimum use of intelligence information within a 
framework of administrative simplicity consistent with 
protection of sensitive intelligence sources, methods 
and analytical procedures. 

g. Ensuring the development, review and maintenance 
of security standards and procedures for the protection 
of intelligence information stored in, processed or 
communicated by computers. 

h. Establishing and directing a research and develop- 
ment program leading to improved security equipment and 


techniques. 
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i. Ensuring that unauthorized disclosures of 


intelligence information are identified and evaluated, 


and that they are subject to investigation as appropriate 
or are referred for investigation pursuant to section 1-707 
of Executive Order 12036. Reporting to the Director of 
Central Intelligence on significant disclosures and 
resultant damage to the intelligence process, sources 

or methods, and providing him with recommendations for 
dealing with the problem. 

2. Functions 

The functions of the committee are: 

a. To advise and assist the Director of Central 
Intelligence in the development and review of uniform 
Intelligence Community security policies, standards, 
procedures and practices for the protection of intel- 
ligence information from unauthorized disclosure. 

b. To review, formulate and recommend to the 
Director of Central Intelligence policies, standards and 
procedures for Intelligence Community application governing 
the dissemination of intelligence information, the 
security of such information released to foreign govern- 
ments and international organizations, and the security of 
intelligence information released to the public or con- 


sidered for such release. 


~ 


Approved For Release 2005/02/15 : CIA-RDP96B01172R000300010009-0 


Approved rola ease 2005/02/15 : CIA-RDP96B0117@#000300010009-0 


_ CONFIDENTIAL 


c. To recommend to the Director of Central 


Intelligence procedures to guard against over- 


classification of intelligence information and to 


ensure uniform handling of challenges to classifications 
of such information as may be made pursuant to section 
5-404 of Executive Order 1206S. 

d. The functions of the committee as they relate 
to technical surveillance countermeasures, computer 
security, special security compartmentation, security 
research and development, and unauthorized disclosures 
investigations are set forth in Attachments 1 through 5. 
3. Community responsibilities 

a. Upon request of the committee chairman, Intel- 
ligence Community organizations shall furnish to the 
committee within established security safeguards particular 
information or materials needed by the committee and 
pertinent to its functions. 

b. The head of each Intelligence Community 
organization shall investigate any unauthorized disclosure 
or compromise of intelligence information occurring within 
his organization. The circumstances underlying and the 
results of such investigations shall be reported to the 
Security Committee chairman in all cases. When investigation 
on an initiative basis or as requested by the Security 
Committee chairman or his designee determines that the 
possibility of compromise cannot be discounted, the 
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results of the investigation, together with an assess- 
ment of the disclosure's impact on national security, 
shall be forwarded to the Security Committee for 
referral to the Director of Central Intelligence through 
the National Foreign Intelligence Board. 
4. Composition, organization and rules of procedure 

a. The composition, organization and rules of 
procedures of the Security Committee are those stated 
in DCID 1/73: 


b. The committee will be supported by 


The chairmen of these 
subcommittees will be designated by the committee 
chairman with the concurrence of the Director of 


Central Intelligence. 


STANSFIELD TURNER (DRAFT) 


Attachments (5) 
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DRAFT 


DIRECTOR OF CENTRAL INTELLIGENCE DIRECTIVE NO. 1/11 
(Attachment 2) 


COMPUTER SECURITY 


The Security Committee with respect to computer security 
shall: 

1. Review, formulate and recommend to the Director 
of Central Intelligence policies, standards and procedures 
to protect intelligence data stored in,processed or communicated 
by computers. 

2. Advise and assist the Director of Central Intelligence, 
Intelligence Community organizations, DCI committees and other 
intelligence users with respect to all computer security issues; 
and to wesotue conflicts that may arise in connection therewith. 

3. Formulate and recommend to the Director of Central 
Intelligence resource programming objectives for Intelligence 
Community organizations in the field of computer security in 
consideration of current and foreseen vulnerabilities and 
threats and with regard for the effective and efficient use 
of resources; to foster and to monitor an aggressive program 
of computer security research and development in the Intelligence 
Community in order to avoid unwarranted duplication and to 


assure the pursuit of an effective effort at resolving technical 
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problems associated with the protection of computer operations. 
4. Coordinate all aspects of Intelligence Community 
efforts in defense against hostile penetration of Community 
computer systems and as feasible to support other governmental 
efforts aimed at improving computer security technology; to 
foster a coordinated program of Intelligence Community 
computer security training and indoctrination. 
ou. Pacrbitate within tne Intelligence Community the 
exchange of information relating to computer security threats, 
vulnerabilities and countermeasures by providing a focal 
point for: 
a. The evaluation of foreign intentions and 
capabilities to exploit Community computer operations; 
b. Central notification of exploitation attempts; 
c. The preparation of damage assessments of 
incidents of exploitation of intelligence computer 
operations; and 
d. The development of policy recommendations to 
the Director of Central Intelligence on the release of 
computer security information to foreign governments 
and international organizations. 
6. Review, formulate and recommend minimum computer 
security standards, procedures and criteria as guidance for 
system design, evaluation and certification of acceptable 


levels of security for computer systems. 
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DIRECTOR OF CENTRAL INTELLIGENCE DIRECTIVE NO. 1/11 
(Attachment 4) 


RESEARCH AND DEVELOPMENT 


The functions of the Security Committee as they relate 
to research and development include: 

1. With respect to general technical surveillance 
countermeasures research and development: 

a. To establish and direct a program of research 
and development leading to improved technical surveillance 
countermeasures equipment and techniques. 

b. To coordinate research and development programs 
in the technical countermeasures field, particularly to 
ensure an effective exchange of information and to avoid 
duplication. 

c. To promote joint development and procurement 
of specialized items of technical surveillance 
countermeasures equipment where cost savings or increased 
security can be achieved through interagency exchange of 
prototype equipment for evaluation purposes and through 
joint procurement activities. 

dw “Ie estcerten and coordinate research and 
development programs in such related areas as physical 


security devices and computer security systems. 
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2. With respect to nieieal Security, computer security 
and other technical aspects of security: 
To initiate and coordinate research and develop- 
ment programs required to support the other missions 
of the Security Committee. 
3. With respect to foreign technical threats: 
To identify and consider any new foreign technical 
threats in the field of security resulting from advances in 


US or foreign technology. 
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DIRECTOR OF CENTRAL INTELLIGENCE DIRECTIVE NO 1/11 
(Attachment 5) 


UNAUTHORIZED DISCLOSURES INVESTIGATIONS 


The functions of the Security Committee with respect to 
unauthorized disclosures* of intelligence information are: 

1. Establish standards for and ensure the timely review 
of compromises or potential compromises of intelligence infor- 
mation to determine if they represent a current and significant 
unauthorized disclosure of properly classified intelligence 
information. 

2. Develop and maintain for Community use a standard 
format for recording and reporting to the Security Committee 
all information pertinent to the identification and assess- 
ment of unauthorized disclosures, including uniform criteria 
for assessing damage from disclosures. Establish and maintain 
a central data base for all information so reported, and for 
data otherwise provided on unauthorized disclosures. 

3. Develop criteria for and ensure that Community agen- 
cies conduct prompt internal investigations of unauthorized 
disclosures when circumstances indicate the compromise may 
have been of internal origin. 

4. Develop standards for use by heads of Community agen- 
cies in referring "cases involving serious or continuing 

*Unauthorized disclosure means the compromise or possible 
compromise of intelligence information through public media 
disclosure, negligence, accident or espionage. With respect to 
the latter cause, the Subcommittee's responsibility is limited to 


providing a damage assessment to the DCI at the conclusion of any 
investigation or when the espionage activity is disclosed. 
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breaches of security" to the Attorney General for FBI inves- 
tigation pursuant to section 1-707 of Executive Order 12036. 

5. Establish and maintain liaison within the Community, 
and with those components of the Department of Justice and 
FBI which are involved in pobeeurs pursuant to section 1-707 
of Executive Order 12036, to ensure prompt coordination and 
resolution of issues pertaining to the identification, assess- 
ment and investigation of unauthorized disclosures. 

6. Monitor the application of administrative sanctions 
pursuant to section 5-502 of Executive Order 12065 when 
investigation shows that an officer or employee of a Community 
agency is responsible for an unauthorized disclosure, and pro- 
vide reports thereon to the DCI with recommendations for any 
appropriate additional action. 

7. Recommend policy and procedural changes for Community 
application to reduce the likelihood of future disclosures or 
minimize their damage. 

8. Propose for referral to appropriate legal. counsel 
recommendations for legislation to improve the protection of 
intelligence information against unauthorized disclosure. 

9. Report annually to the DCI on the past year's 


experience in unauthorized disclosures. 
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